Who sent the email? IT Security

Soldato
Joined
25 Aug 2006
Posts
6,377
Morning all,

Random question of the day!

A client of ours mentioned in passing that they had received an email from a .ac.uk address to their personal hotmail account. I offered to have a quick look at the email and what i have learned:

a. Contents is definitely spam ie 'reply here to get your millions' with the link being to a @163.com email (Chinese free email account).

b. The senders email address is detailed as a member of the University (quick google of the uni sites shows the person works there ie [email protected]

I am thinking that the email has been spoofed or the uni account hacked/compromised. I have got the email headers (but to be honest i am not sure what i am looking for there - lol!)

Any ideas from my geek brethren?
 
Associate
Joined
26 Mar 2015
Posts
1,004
Location
West Midlands
My general assumption would be that member of staff from the university has put their password somewhere onto a forged site or something along them lines, possibly after following an email link to 'download an email attachment'. All scripted that the moment the bot has access to someone's email, they'll spam an email to anyone/everyone.
 
Associate
Joined
20 Aug 2003
Posts
2,139
Location
The Republic
My general assumption would be that member of staff from the university has put their password somewhere onto a forged site or something along them lines, possibly after following an email link to 'download an email attachment'. All scripted that the moment the bot has access to someone's email, they'll spam an email to anyone/everyone.

This. The uni in question should have an [email protected] address (or similar, Google it), they'd appreciate it if you forwarded on the email with a "looks like you've got a compromised account" message. They'll be used to dealing with this sort of thing, as academics have a tendency to be astonishingly stupid sometimes (I had one who put his bank details into a phishing link even though it was for a different bank......)
 
Associate
Joined
30 Jan 2011
Posts
280
Location
UK
Mostly email has been hacked spoofed..i would have them reset their passwords and confirm if they recently entered their email in any doggy third party site
 
Soldato
Joined
3 Dec 2002
Posts
4,002
Location
Groovin' @ the disco
This is the issue where users use their work email address for personal reasons!

The sad thing is that most don't know any better not to use it... for goodness shake; just sign up for a free online mail account.
 
Back
Top Bottom